PREPRINT – accepted for publication at the 7th IEEE International Conference on Autonomic Computing and Self-Organizing Systems (ACSOS) 2026
Extending Decision Maps for Sustainable Safety and Security in Self-Adaptive Systems Marco Stadler (Johannes Kepler University Linz, LIT Secure and Correct Systems Lab / Institute of Business Informatics – Software Engineering; [email protected]) Wesley K.G. Assunção (North Carolina State University, Department of Computer Science; [email protected]) Michael Vierhauser (University of Innsbruck, Department of Computer Science; [email protected]) Iris Groher (Johannes Kepler University Linz, Institute of Business Informatics – Software Engineering; [email protected]) Michael Riegler (ENGEL Austria GmbH, Information Security; [email protected]) Johannes Sametinger (Johannes Kepler University Linz, LIT Secure and Correct Systems Lab / Institute of Business Informatics – Software Engineering; [email protected]) DOI: TBA
arXiv:2607.11274v1 [cs.SE] 13 Jul 2026
ABSTRACT Sustainability refers to a system’s ability to maintain its functionality and endure over time. Hence, sustainability is a highly desirable property of software systems, including Self-Adaptive Systems (SASs). SASs can change (adapt) their behavior at runtime to continue achieving their objectives despite external or internal impacts. SASs’ intended long-term system behavior can be expressed through a sustainability-driven visual modeling notation called Decision Maps (DMs). Although DMs have been proven helpful, they lack adequate modeling support for safety and security concerns. We address this limitation by extending the current notation for sustainability-driven modeling of SASs to better accommodate the unique characteristics of safety and security scenarios. First, we introduce an additional modeling dimension to account for safety incidents. Second, we adopt a fine-grained divide-and-conquer approach, modeling from distinct temporal security viewpoints (“security modes”) to address security. We employ the extended DM notation in a real-world use case scenario provided by our industry partner to assess its feasibility and suitability for practitioners. Our results indicate that our modeling notation helps capture security and safety scenarios more accurately and provides holistic support for the self-adaptation life cycle phases.
time, it must meet its corresponding security and safety intents. While SAS engineering addresses primarily long-term technical sustainability (e.g., maintainability [7]), runtime adaptation typically optimizes for short-term technical properties [8] such as performance, reliability, or availability [9, 10, 11]. Such a shortterm focus often neglects a holistic sustainability perspective that explicitly balances safety and security as core pillars alongside environmental and social concerns. Sustainability modeling [12] offers a complementary perspective, framing adaptation as a long-term, value-driven process, rather than an immediate technical reaction. In this context, sustainability refers to a system’s ability to endure and maintain effective operation over prolonged periods [8, 12, 13, 6]. Anderson [14] defines sustainability in the context of security as the capability to maintain safety-critical security properties over the long operational lifetime of systems through continuous update, maintenance, and governance.
1 Introduction
The combination of sustainability and self-adaptation allows for modeling the adaptation intent as a sustainability goal aimed at achieving the long-term success of an SAS [8]. The core idea hereby is to express the adaptation intent at design time using a visual notation called Decision Maps (DMs) [15] to analyze its impact both at runtime and over prolonged periods of time [8].
Software systems that handle distributed applications in dynamic environments typically require human oversight to operate both reliably and safely [1]. Self-adaptive systems (SASs) commonly address this challenge by employing a feedback loop mechanism that autonomously adjusts to, for example, environmental changes to preserve the system’s utility without constant human intervention [1]. In many domains, SASs often also exhibit safetyand security-critical characteristics [2, 3, 4]. For instance, a selfadaptive robotic system should never harm the humans working in close proximity (safety), nor should it be possible for a malicious actor to trigger such behavior (security). These characteristics can be denoted as software intents, describing the essential sustainability boundaries on, and expectations of a system’s behavior [5, 6]. Hence, for a software system to preserve safety and security over
Continuously monitoring a system and its environment, analyzing the monitored data, and determining an adaptation action are among the significant challenges faced by practitioners [8]. This problem becomes even more complex in safety- and securitycritical environments [2], requiring guidance and proper tool support to assess and integrate safety and security impacts. Current DM-based modeling techniques [12, 8] capture adaptation intents, but cannot express fine-grained sustainable safety or security concerns. Furthermore, security incidents cause a shift in priorities at runtime, which is not covered by existing sustainability models [12]. Thus, SASs operating in safety- and security-critical environments need extended modeling capabilities that combine sustainability goals with system states during an attack. Therefore, our work is motivated by the following research questions 1
PREPRINT – accepted for publication at the 7th IEEE International Conference on Autonomic Computing and Self-Organizing Systems (ACSOS) 2026 (RQs): • RQ1: What concepts and extensions are needed to enhance the sustainability-driven DM modeling notation so that it can represent safety- and security-aware adaptation intents in SASs? • RQ2: To what extent is the extended DM notation feasible for capturing sustainable safety- and security-relevant adaptation intents in real-world and benchmark SASs? We build on the DM modeling notation and augment it with new semantic elements to more accurately capture and sustain the long-term adaptation intent. Our results demonstrate that the extended notation captures safety and security intents, explicitly exposing dynamic trade-offs for compensatory adaptation that overcome the limitations of static modeling. With this work, we contribute to the broader notion of achieving long-lasting (sustainable) adaptive software systems used in both safety- and security-relevant environments.
2 Background SASs are systems capable of modifying their structure or behavior at runtime to maintain their goals despite environmental or internal uncertainties [1]. SASs are usually divided into a Managed system (the application logic subject to change) and a Managing system (the adaptation logic that performs the runtime changes) [9, 16, 8], acting as a feedback loop, most commonly realized through the MAPE-K reference model, which Monitors, Analyzes, Plans, and Executes adaptations over a shared Knowledge base [9, 17, 18]. Sustainability Modeling and Evolution of Quality Concerns: Software sustainability is defined as “the preservation of the long-term and beneficial use of software, and its appropriate evolution, in a context that continuously changes” [6, 13]. Lago et al. [12] developed the Sustainability Assessment Framework (SAF) Toolkit that provides support for modeling sustainability as a software quality property and includes DMs, which show sustainability trade-offs and dependencies among quality attributes. It further contains a “Sustainability-Quality model”, which categorizes and measures quality attributes across four dimensions: 1) social, the integration of systems within communities taking into account their impact on society; 2) technical, the evolution, maintenance, and long-term utilization of software systems; 3) environmental, the impacts on the natural ecosystem, greenhouse gas emissions, etc.; and 4) economic, the business considerations [19, 15, 8, 12, 6]. DMs are used to illustrate the features of a selected software project that should be sustainability aware. Stakeholders use a DM to reason about the implications of the design decisions made and their effect on the quality attributes, which are categorized using the four previously outlined dimensions. Effects on quality attributes can be either positive, negative, or undecided. The quality attributes are further detailed by mapping them across the sustainability-time dimensions [20]. The impacts of information and communication technology (ICT) can take either direct (i.e., IMMEDIATE) effects, ENABLING effects, or SYSTEMIC effects.
Positive,
negative,
or
neutral effects of adaptation on quality concern
Max Quality Concern
Underperforming
Sustainability Boundaries
Compensating
Min
Modes: normal
DoS attack
recovery
normal
time
Figure 1: Evolution of quality concerns over time with compensatory adaptation (adapted from [8, 12]).
Gerostathopoulos et al. [8] proposed to combine sustainability modeling with SASs, modeling the so-called adaptation intent of a managed system as a sustainability goal. By preserving the original intent of the managed system, the SAS can accommodate changes over time, and only then, they can be considered truly successful. The novel idea is that an adaptation (i.e., one MAPE-K loop) in an SAS is usually only concerned with a short period of time. In essence, adaptation can enrich its short-term perspective with a long-term perspective through sustainability [8]. Security: Security in software systems is defined as the protection of information and resources to ensure confidentiality, integrity, and availability [21]. Maintaining security is challenging, as it is not a static property but a dynamic state that must be actively defended. A system may be considered “secure” at one point in time, and after a new vulnerability is disclosed, the attack surface can change completely. The Log4Shell vulnerability [22] is a prominent example, allowing remote code execution in the widely used Log4j Java logging framework: disclosed on 9 December 2021, it rendered systems that were considered secure the day before insecure overnight. Hence, systems must co-evolve (adapt) with the threat landscape to effectively protect their resources. SASs capable of protecting and mitigating security threats at runtime are called self-protecting software systems [23]. One concept SASs use is security modes, which decompose a system into multiple operational modes [24, 25, 26, 27]. Each mode denotes a distinct operational state defined by its own set of resource configurations and tasks [28]. For instance, a web server can be split into a normal mode and a vulnerable mode: the web server enters the vulnerable mode when a new vulnerability (like Log4Shell) is published but no fix is yet available, trading off properties such as functionality, availability, or energy efficiency for security (e.g., restricting access or up-scaling resources). The web server switches back to normal mode once the fix is installed. Security modes were proposed as early as 2001 [29] and have since been used in the SASs community [30, 24]. Safety: Safety refers to “the absence of catastrophic consequences on the user(s) and the environment” [31]. Safety and security are interconnected concepts. Security influences the functional safety of systems [2]. For instance, a security issue becomes a safety risk if hackers manage to access pacemakers and alter the clock rate or set off emergency shocks, harming patients [32]. Penzenstadler et al. [34] argue that safety and security are not merely operational constraints but foundational pillars that enable 2
PREPRINT – accepted for publication at the 7th IEEE International Conference on Autonomic Computing and Self-Organizing Systems (ACSOS) 2026 TYPES OF DIGITAL FEATURES OR REQUIREMENTS FEATURE OR REQUIREMENT FEATURE OR (SOCIAL) REQUIREMENT FEATURE OR (TECHNICAL) FEATURE OR REQUIREMENT (ECONOMIC) FEATURE OR REQUIREMENT (INDIVIDUAL)
New/changed notation elements
REQUIREMENT (ENVIRONMENTAL)
FEATURE OR REQUIREMENT (GENERIC)
TYPES OF INTERDEPENDENCIES
TYPES OF SUSTAINABILITY QUALITY-CONCERNS
+
POSITIVE EFFECT
-
NEGATIVE EFFECT UNDECIDED EFFECT REQUIREMENT
SOCIAL CONCERN
ENVIRONMENTAL CONCERN
TECHNICAL CONCERN
ECONOMIC CONCERN
COMMENT (E.G., EFFECT CAUSE; MEASURE; PREDICTION)
SOFTWARE ARCHITECTURE MODES M1: M2: M3: DEFEND RECOVERY NORMAL
Mn: ...
INDIVIDUAL CONCERN
SUSTAINABILITY IMPACTS SYSTEMIC
ENABLING
IMMEDIATE
Figure 2: Extending the DM notation of Lago et al. [12] (colors have been adapted for colorblind accessibility [33]).
a DoS attack, the immediate priority shifts to system resilience, with a technical focus on guaranteeing safety and availability to ensure correct operation under severe stress. The existing DM notation only supports modeling adaptation intents statically along four sustainability dimensions. Security incidents are modeled as generic disruptions, failing to capture the changing priorities or trade-offs in each attack life cycle phase. Furthermore, environmental aspects such as energy spikes during countermeasures and normalization in recovery are indistinct, and the fact that security adapts over time, shifting from containment to restoration, is absent.
3 Related Work a system’s long-term endurance. For systems involving humans in the loop, sustainable safety means preserving the individual’s well-being over time. For instance, by preventing operator fatigue, chronic stress, or cognitive overload that could lead to future accidents. The recent ISO/IEC 25010:2023 standard [35] explicitly elevates Safety to a primary quality characteristic, yet current sustainability modeling approaches [12] still aggregate safety and related human concerns under a broad “social” dimension. This aggregation limits the ability to reason about and operationalize these concerns in SASs. Hence, SASs require a more fine-grained perspective that explicitly distinguishes and represents such concerns. This explicit representation is a prerequisite for achieving sustainable safety. Running Example: Safety – Machine workers are working in close proximity to a robotic system to assemble parts (“cobots”) [36], with a supervising human-in-the-loop part of the SAS [37]. A human can shut down a robot if a sensor alert is detected, but they need to determine if the alert is a true positive and confirm a real emergency situation. Although the system is designed to provide technical resilience to ensure safe operation, a fatigued operator with manual override privileges may still circumvent these safeguards. The current dimensions of the modeling notation cannot capture this critical sustainability concern: The social dimension focuses on communities/collective welfare [19], rather than individual cognitive or behavioral factors such as fatigue or situational awareness. The technical and economic dimensions represent system and cost optimization; they model performance, maintainability, and resource use, but not human reliability. The environmental dimension focuses on ecological effects [19]. Therefore, a person-centric perspective is necessary; sustaining this resilience over the long term requires modeling human cognitive degradation. Security – Continuing with the above example, we assume that cobots are working in a warehouse production line orchestrated by an industrial control system (ICS). For instance, consider a Denialof-Service (DoS) attack targeting the ICS. A DoS attack’s goal is to tamper with the availability of a target system by generating a large volume of traffic, depleting the target’s infrastructure [38]. In a standard operational context, the sustainability goal is to minimize energy consumption to reduce the carbon footprint; therefore, a static DM would model a “high energy” state as a negative impact on the environmental dimension. However, during
Sustainability in software engineering (SE) has gained increasing importance [39, 6] and has been discussed in domains such as requirements engineering (RE) [40], software architecture [41], and development [42]. Many sustainability approaches in SE focus on assessing the potential sustainability impacts of software systems during RE activities [34, 43]. A mapping study by Bambazek et al. [40] identified the Sustainability Awareness Framework (SusAF) [44] as one of the most established methods. It provides structured guidance for facilitating sustainability workshops and employs a set of guiding questions to help practitioners recognize possible sustainability impacts of software systems. Early work on contextual RE introduced goal-oriented models [45]. The idea of modeling adaptation intents as sustainability goals was initially proposed by Gerostathopoulos et al. [8] and was subsequently used in a series of studies. For instance, H𝑎𝑟𝑚𝑜𝑛𝐸 leverages the approach to incorporate self-adaptive capabilities into MLOps pipelines to support long-term sustainability [46, 47]. Recent work has combined contextual goal models with proactive self-adaptation mechanisms, for example by integrating goaloriented requirements with control-theoretic approaches to adapt system behavior under changing context [48]. They largely focus on qualities such as reliability or efficiency but do not explicitly address sustainability concerns. Some studies discuss the notion of combining adaptive security and (partially) sustainability. For instance, Halabi et al. [49] propose to use adaptive cybersecurity for Green IoT focusing on the “energy-efficient and environmentfriendly paradigm”. Hence, existing work almost exclusively focuses on the environmental dimension, treating sustainability, safety, and security as separate concerns. The SAF Toolkit, developed by Lago et al. [12], provides comprehensive support for modeling sustainability and covers important system characteristics. However, the SAF Toolkit lacks dedicated support for requirements, particularly for safety- and securitycritical systems and self-adaptation. The solution we propose in this paper specifically addresses these challenges by extending the SAF Toolkit notation to explicitly capture security, safety, and health concerns, and by introducing novel mechanisms for handling and executing dynamic behavior based on security modes.
4 Approach To address the aforementioned problems and challenges, we extend the current DM notation with additional semantic elements 3
PREPRINT – accepted for publication at the 7th IEEE International Conference on Autonomic Computing and Self-Organizing Systems (ACSOS) 2026 COBOT PRODUCTION ASSEMBLY
SUPERVISE COBOT OPERATION
-
OPERATOR FATIGUE
Figure 3: Individual dimension in the running example.
(cf. Fig. 2). It is important to note that the extended DMs intend to function in conjunction with established dependability engineering practices. We assume that rigorous threat modeling [50] (e.g., attack trees [51]) or hazard analysis [52] (e.g., fault trees [53, 54]) has been performed, identifying vulnerabilities and safety concerns. Extension 1 – Individual Dimension: The current notation for modeling sustainability goals using DMs consists of four dimensions: social, technical, environmental, and economic (cf. Section 2). While these four dimensions have proven to be sufficient for several use cases (e.g., [47]), we argue that from a safety perspective, it is beneficial to introduce a new fifth dimension: the individual. The individual dimension is, among others, inspired by the SusAF [34, 55, 56]. The dimension in SusAF covers the topics lifelong learning, privacy, agency, as well as health and safety [55]. They define health as “the state of a person’s mental or physical condition” [56]. For the health topic, the framework tries to answer the question of how the system can improve or worsen a person’s physical, mental, and/or emotional health. The safety topic in SusAF refers to the protection from danger, risk, or injury [56]. More specifically, for the safety topic, it tries to answer how the system exposes (or protects) a person from physical harm and how it makes a person feel more (or less) exposed to harm. It also includes the question of what happens if the system is used in an unintended way and the influence of such an event on an individual’s safety. Hence, we suggest leveraging this already well-established and defined sustainability dimension in the (RE) sustainability community and combining it with the DM notation. We propose to extend and incorporate the notion of the individual dimension to capture an individual’s safety and health more accurately over a long period of time. The resulting notation is shown in Fig. 2. In particular, we propose to extend the TYPES OF DIGITAL FEATURES OR REQUIREMENTS with an additional FEATURE OR REQUIREMENT (INDIVIDUAL) and add an additional component to the TYPES OF DIGITAL FEATURES OR REQUIREMENTS called an INDIVIDUAL CONCERN . With this additional dimension, we can model safety-relevant concerns in the DMs and address further requirements related to an individual’s well-being. Importantly, a single safety requirement can be met by different alternative features. The extended DM notation allows users to explicitly model these feature choices, making it easier to compare their unique sustainability and socio-technical trade-offs to select the most suitable option. Applying this to our running example introduced in Section 2, we can now model the machine worker’s fatigue using our new notation elements (cf. Fig. 3). We model the requirement SUPERVISE COBOT OPERATION as a FEATURE OR REQUIREMENT (INDIVIDUAL) . We explicitly link this
requirement to the INDIVIDUAL CONCERN OPERATOR FATIGUE with a negative effect. This visualizes that while the human’s validation is necessary for safety (resolving false positives), the repetitive cognitive demand of this task negatively impacts the operator’s long-term well-being and reliability. Extension 2 – Security Modes: Security is a cross-cutting concern that intersects with all sustainability dimensions. For example, user privacy (social), sensor data privacy (environmental), resilience against cyberattacks (technical), and reduced risk of financial loss (economic). Thus, security is not a standalone pillar, but rather an essential quality that influences and reinforces sustainable outcomes [34]. Security is not static, it is an evolving system property. Our example of the Log4Shell vulnerability, and the DoS attack in our running example illustrate how requirements on a software system can change over the course of an attack. The current DM notation’s capability of modeling changing requirements (dynamic behavior) is limited [8]: “Throughout a project, a DM can be updated to reflect, e.g., changes in requirements or a better-informed understanding of the expected or actual effects.” When modeling sustainable security, we can therefore already be certain that a model created with the current DM notation is subject to change. Instead of assuming the DM model “as is” and updating it to changing requirements (suggested in [8]) once a security incident has already happened, we advocate for proactively leveraging the dynamics of an attack and modeling the software system from different security viewpoints already at design time. Analogous to security threat modeling [50], which involves analyzing potential threats at design time and then proposing appropriate mitigation techniques, we argue that by proactively investigating the timing dynamics of an attack already when modeling the adaptation intents, we can identify potential quality concerns and, most importantly, the corresponding changing system requirements beforehand. We propose extending the DM notation by modeling security in the DMs using security modes. The security modes contextualize a system based on different attack stages or attack surface (e.g., vulnerable mode vs normal mode for the web server in Section 2). By using the security modes during DM modeling, we actively explore the system space along the attack stages and capture the implications of each security mode separately. Each identified change is then modeled as part of the DM and does not need to be manually changed at runtime later on in the DM. As a result, this yields multiple DMs, one per mode, for the same software system. For the notation elements, we introduce SOFTWARE ARCHITECTURE MODES in Fig. 2 to support this extension. For each mode, it is possible to capture the (security-relevant) concerns. For the running example in Section 2, because of this extension, it is possible to model the DMs individually for each security mode. For each security mode, we create a dedicated DM, thus capturing the implications during a DoS attack (M1: DOS DEFENSE), during attack recovery (M2: ATTACK RECOVERY), or during normal operation times (M3: NORMAL MODE). While we focus on security incidents here, this extension natively supports safety contexts (e.g., an “Emergency Shutdown Mode”). Compensatory Adaptation: With our extensions (especially 4
PREPRINT – accepted for publication at the 7th IEEE International Conference on Autonomic Computing and Self-Organizing Systems (ACSOS) 2026 SYSTEMIC
SYSTEMIC
ENABLING
ENABLING IMMEDIATE M1:DOS DEFENSE
COMMUNICATE TO PUBLIC
-
-
INCIDENT RESPONSE TEAM STRESS
INFRASTRUCTURE COSTS
SCALE-UP SYSTEMS +
-
MACHINE AVAILABILITY WORKER SAFETY
ENERGY CONSUMPTION
IMMEDIATE
EMPLOYEE SATISFACTION
PROMOTE WORK-LIFE BALANCE
M2:ATTACK RECOVERY
+
RELEASE INCIDENT HANDLING REPORT
SENSITIVE CUSTOMER DATA
CHECK MACHINE SAFETY + SAFETY OF MACHINE WORKERS
+
COMPANY REPUTATION
INCIDENT RESPONSE TEAM STRESS +
INFRASTRUCTURE SCALE-DOWN + COSTS SYSTEMS +
CARBON FOOTPRINT
+
+
ENERGY CONSUMPTION + PURCHASE CARBON OFFSETS +
EMPLOYEE SATISFACTION
CARBON FOOTPRINT
COMPANY REPUTATION
(a) DM for “DOS DEFENSE MODE”.
(b) DM for “Attack Recovery Mode”. Figure 4: DMs for the industrial use case.
the security modes), we provide conceptually a new perspective on the evolution of quality concerns and the adaptations over time. Related work expressed the sustainability boundaries (cf. Max and Min in Fig. 1) as the target adaptation space for quality concerns. This means that adaptations and effects should only happen within the sustainability boundaries to meet the initial adaptation intent. We argue in this paper that this is not realistic in safety and security scenarios, where priorities shift over time.
5 Evaluation 5.1 Methodology
By modeling the target system over time at design time, we can identify the aforementioned trade-offs in quality concerns preemptively and deal with the degradation of quality concerns in extreme situations. Consider Fig. 1: We can use the security modes to anticipate potential degradations at design time. For instance, during the DOS DEFENSE MODE, we then know that certain quality concerns are not within our sustainability boundaries. We can use this knowledge to introduce and enter a recovery mode where we make up for the underperforming time, i.e., we enter a compensation stage, to make up for the underperforming (but necessary) times.
one of the leading manufacturers of injection molding machines. In practice, these machines operate largely isolated from public networks (e.g., in segmented or even air-gapped production environments) and are protected by established security measures, so a scenario such as the one modeled below is highly unlikely to occur in the field. Nevertheless, because downtime (e.g., due to a security incident) could severely disrupt operations and cause significant financial losses, and because the safety of workers operating close to the machines is paramount, such worst-case scenarios are exactly what practitioners must reason about at design time. Therefore, the company serves as an excellent case
To validate our proposed approach, we use the extended DM notation in a series of use cases. Due to space restrictions, we report only one use case: an industrial proof-of-concept validation. The industrial proof-of-concept use case is motivated by our industry partner (details in context description). Using the extended DM notation in a realistic use case scenario showcases the practical We illustrate this using the cobots running example (cf. Sec- relevance of our approach. tion 2): In the event of a safety emergency (e.g., confirmed alert The SASs research community has accumulated several “exemwith the cobot), the priorities of an organization/system shift to plars” over the years [58]. The idea is to use SASs exemplars to protect human lives at all cost, as this is of utmost importance at promote active research, share common adaptation problems, and this very moment. During this shift in priorities, other sustainabil- facilitate research in general [59]. In our evaluation (due to space ity quality concerns degrade. For instance, there might be a direct restrictions not reported here), we tested our approach also using economic loss because of the immediate shut down of the cobot the DeltaIoT [60] and SWIM [61] exemplars. manufacturing line. One can observe a similar shift in priorities in Our approach outlines two major extensions (Extension 1 – Inthe event of a security incident. The average impact of a successful dividual Dimension & Extension 2 – Security Modes) and an impact attack on a company’s ICS costs a company $5 million, 50 days on the evolution of adaptations (Compensatory Adaptation). To anof downtime, and it takes around 191 days for an organization to swer RQ2 (feasibility), we report for one use case the implications fully recover from an incident [57]. Hence, for an organization to of using the two extensions and what the new perspective for the stay economically competitive, it will prioritize warding off any specific use case implies. This allows for a well-informed decision attack that compromises the availability of the production line on whether our proposed extended DM notation is indeed feasible. (e.g., a DoS attack) and trade it off with other quality concerns. For instance, the employee satisfaction of a security team will 5.2 Industrial Use Case degrade because of overtime to close the vulnerability. Hence, we The use case is motivated by our industry partner. ENGEL Aussee the shift of priorities as unavoidable and as a more realistic tria GmbH is a large machine manufacturing company, operating viewpoint in these types of systems. in over 80 countries, with several thousand employees, and is
5
PREPRINT – accepted for publication at the 7th IEEE International Conference on Autonomic Computing and Self-Organizing Systems (ACSOS) 2026 study. We use our extended notation to model an injection molding machine under a DoS attack (e.g., from a peripheral network). Fig. 4a shows the sustainability goals during the DoS attack, and Fig. 4b shows them during recovery from the attack. Extension 1 – Individual dimension: During the attack, the infrastructure will be scaled up. Although this requirement has a positive effect on AVAILABILITY, MACHINE WORKER SAFETY , and the security of SENSITIVE CUSTOMER DATA , it also has several negative side effects. As infrastructure costs rise, the INCIDENT RESPONSE TEAM STRESS increases, and the ENERGY CONSUMPTION rises. Furthermore, disclosing the attack to the public might influence the company’s reputation. However, in the interest of safety and availability, all these negative effects are unavoidable short-term effects. During recovery, we are able to capture (among other concerns) the inverse safety intents of the DoS attack: the company can PROMOTE WORK-LIFE BALANCE to eventually reduce INCIDENT RESPONSE TEAM STRESS and increase EMPLOYEE SATISFACTION . Extension 2 – Security modes: In the given scenario, the system is modeled to operate in two security- and safety-relevant operational modes: M1: DOS DEFENSE – i.e., during the DoS attack; M2: ATTACK RECOVERY – i.e., after the attack has been warded off. As a result, we are able to capture the timing-specific implications of the different modes. Compensatory Adaptation: Based on an analysis of the previously outlined defense mode, it is possible to address neglected sustainability quality concerns to restore balance in the adaptation intent. When the system is in defense mode (M1: DOS DEFENSE), the priority is to minimize the impact of the attack; hence, the immediate actions taken by the incident response team and the SAS are scaling up the infrastructure. In particular, the negative effects in M1 (cf. red arrows in Fig. 4a) should be used to identify potential countermeasures (i.e., positive effects) to meet the overall sustainable adaptation intent. For instance, to recover from the stress of the DoS attack, the incident response team can take additional time off to make up for the distress.
satory adaptation mechanisms (cf. recovery modes in Section 5). Consequently, our approach identifies (negative) effects and proactively finds ways to adapt in accordance with sustainability goal intents. A visualization of the quality of a sustainability goal over time with active compensation is shown in Fig. 1. In a realistic scenario, a cyber attack will always shift priorities, thereby resulting in underperforming quality for some sustainability goals (red area). However, our approach allows us to identify those negative effects and, at the same time, plan for adaptation opportunities for compensation (green area). Taking all of the above into consideration, the answer to RQ1 can be summarized as follows: Answer to RQ1 – Two extensions are needed to express the safety- and security-aware adaptation intent: First, an additional individual dimension to model safety and humancentric concerns. Second, security modes enable us to express shifting sustainability concerns over time. Building on our conceptual extensions identified in RQ1, RQ2 examines how the extended DM notation behaves when applied in practice. Particularly, whether the new individual dimension and the use of security modes are usable in practice. We validated the feasibility through application in an industrial domain. The successful modeling leads to the following conclusion for RQ2: Answer to RQ2 – The extended DM notation proved feasible in an industrial manufacturing scenario. The newly introduced individual dimension explicitly captures humancentric safety and health concerns, such as operator fatigue and incident response team stress. Security modes allow modeling multiple operational modes, such as normal operation, different attack phases, and recovery. By capturing system behavior over time, the DMs make security dynamics explicit, and reveal mode-specific trade-offs and compensation strategies.
6 Discussion 7 Conclusion
The goal of our work is to find novel ways for modeling adaptation In this paper, we present an extended DM modeling notation to intents as sustainability goals for safety- and security-critical scesupport SAS safety and security scenarios. The extension supnarios. The implications of our evaluation, applying the extended ports modeling the adaptation intent using sustainability goals notation to the industrial use case, can be summarized as follows: for security and safety scenarios by adding an additional individual dimension and leveraging security modes in the DMs. Our With the newly added individual dimension, we were able to evaluation provides a first indication of the feasibility of our apcapture and model not only safety concerns (e.g., MACHINE WORKER proach. However, extending the current notation is only a first SAFETY in Fig. 4a), but we can also represent a variety of human- step towards achieving a comprehensive, sustainable security and centric concerns, such as the INCIDENT RESPONSE TEAM STRESS. safety support. We envision a full integration into the SAF Toolkit Without our DM notation, these aspects were either not captured pipeline [12] in the future to facilitate true sustainable security or only implicitly and coarsely captured through other dimensions. and safety adaptations. Our extension with the individual dimension directly supports sustainable safety adaptations in SASs. Similar to threat modeling [50], explicitly analyzing worst-case scenarios (cf. defense mode in Section 5) systematically exposes attack impacts and provides the structural basis to design compen6
PREPRINT – accepted for publication at the 7th IEEE International Conference on Autonomic Computing and Self-Organizing Systems (ACSOS) 2026 References [26] R. Romagnoli, B. H. Krogh, D. de Niz, A. D. Hristozov, and B. Sinopoli, “Runtime [1] M. Salehie and L. Tahvildari, “Self-adaptive software: Landscape and research challenges,” ACM Transactions on Autonomous and Adaptive Systems, vol. 4, no. 2, pp. 1–42, May 2009. [2] I. Pekaric, R. Groner, T. Witte, J. G. Adigun, A. Raschke, M. Felderer, and M. Tichy, “A systematic review on security and safety of self-adaptive systems,” Journal of Systems and Software, vol. 203, p. 111716, Sep. 2023. [Online]. Available: https://www.sciencedirect.com/science/article/pii/S0164121223001115 [3] G. Weiss, P. Schleiss, D. Schneider, and M. Trapp, “Towards integrating undependable self-adaptive systems in safety-critical environments,” in Proceedings of the 13th International Conference on Software Engineering for Adaptive and Self-Managing Systems. Gothenburg Sweden: ACM, May 2018, pp. 26–32. [4] S. Chehida, E. Rutten, G. Giraud, and S. Mocanu, “A model-based approach for selfadaptive security in CPS: Application to smart grids,” Journal of Systems Architecture, vol. 150, p. 103118, May 2024. [5] M. Huisman, H. Bos, S. Brinkkemper, A. Van Deursen, J. F. Groote, P. Lago, J. Van De Pol, and E. Visser, “Software that Meets Its Intent,” in Leveraging Applications of Formal Methods, Verification and Validation: Discussion, Dissemination, Applications, T. Margaria and B. Steffen, Eds. Cham: Springer International Publishing, 2016, vol. 9953, pp. 609–625. [6] P. Lago and I. Malavolta, “A New Vision on Software Sustainability and Its Engineering,” IEEE Software, vol. 43, no. 1, pp. 119–123, Jan. 2026. [7] C. C. Venters, C. Jay, L. M. S. Lau, M. K. Griffiths, V. Holmes, R. R. Ward, J. Austin, C. E. Dibsdale, and J. Xu, “Software Sustainability: The Modern Tower of Babel,” in Proceedings of the Third International Workshop on Requirements Engineering for Sustainable Systems, vol. 1216. Karlskrona, Sweden: CEUR Workshop Proceedings, Aug. 2014, pp. 7–12. [8] I. Gerostathopoulos, C. Raibulet, and P. Lago, “Expressing the adaptation intent as a sustainability goal,” in Proceedings of the ACM/IEEE 44th International Conference on Software Engineering: New Ideas and Emerging Results. ACM, May 2022, pp. 36–40. [9] D. Weyns, B. Schmerl, V. Grassi, S. Malek, R. Mirandola, C. Prehofer, J. Wuttke, J. Andersson, H. Giese, and K. M. Göschka, “On Patterns for Decentralized Control in Self-Adaptive Systems,” in Software Engineering for Self-Adaptive Systems II: International Seminar, Dagstuhl Castle, Germany, October 24-29, 2010 Revised Selected and Invited Papers. Berlin, Heidelberg: Springer, 2013, pp. 76–107. [10] T. Wong, M. Wagner, and C. Treude, “Self-adaptive systems: A systematic literature review across categories and domains,” Information and Software Technology, vol. 148, p. 106934, Aug. 2022. [Online]. Available: https://linkinghub.elsevier.com/retrieve/pii/ S0950584922000854 [11] R. Donakanti, P. Jain, S. Kulkarni, and K. Vaidhyanathan, “Reimagining Self-Adaptation in the Age of Large Language Models,” in 2024 IEEE 21st International Conference on Software Architecture Companion (ICSA-C). Hyderabad, India: IEEE, Jun. 2024, pp. 171–174. [12] P. Lago, N. Condori Fernandez, I. Fatima, M. Funke, and I. Malavolta, “The sustainability assessment framework toolkit: a decade of modeling experience,” Software and Systems Modeling, vol. 24, no. 2, pp. 361–383, Apr. 2025. [13] I. Vermeulen, Ed., Connected World: Insights from 100 academics on how to build better connections. VU University Press, 2023. [14] R. Anderson, “Making security sustainable,” Communications of the ACM, vol. 61, no. 3, pp. 24–26, Feb. 2018. [15] P. Lago, “Architecture Design Decision Maps for Software Sustainability,” in Proceedings of the IEEE/ACM 41st International Conference on Software Engineering: Software Engineering in Society. IEEE, May 2019, pp. 61–64. [16] P. Arcaini, E. Riccobene, and P. Scandurra, “Modeling and Analyzing MAPE-K Feedback Loops for Self-Adaptation,” in 2015 IEEE/ACM 10th International Symposium on Software Engineering for Adaptive and Self-Managing Systems, May 2015, pp. 13–23, iSSN: 2157-2321. [Online]. Available: https://ieeexplore.ieee.org/abstract/document/7194653 [17] Y. Brun, G. Di Marzo Serugendo, C. Gacek, H. Giese, H. Kienle, M. Litoiu, H. Müller, M. Pezzè, and M. Shaw, “Engineering Self-Adaptive Systems through Feedback Loops,” in Software Engineering for Self-Adaptive Systems. Berlin, Heidelberg: Springer Berlin Heidelberg, 2009, vol. 5525, pp. 48–70, series Title: Lecture Notes in Computer Science. [18] J. Kephart and D. Chess, “The vision of autonomic computing,” Computer, vol. 36, no. 1, pp. 41–50, Jan. 2003. [Online]. Available: http://ieeexplore.ieee.org/document/1160055/ [19] P. Lago, S. A. Koçak, I. Crnkovic, and B. Penzenstadler, “Framing sustainability as a property of software quality,” Communications of the ACM, vol. 58, no. 10, pp. 70–78, Sep. 2015. [Online]. Available: https://dl.acm.org/doi/10.1145/2714560 [20] L. M. Hilty and B. Aebischer, “ICT for Sustainability: An Emerging Research Field,” in ICT Innovations for Sustainability. Springer International Publishing, 2015, vol. 310, pp. 3–36. [21] M. Nieles, K. Dempsey, and V. Y. Pillitteri, “An introduction to information security,” National Institute of Standards and Technology, Tech. Rep., Jun. 2017. “Inside the Log4j2 vulnerability (CVE-2021[22] J. Graham-Cumming, 44228),” Dec. 2021. [Online]. Available: https://blog.cloudflare.com/ inside-the-log4j2-vulnerability-cve-2021-44228/ [23] E. Yuan, N. Esfahani, and S. Malek, “A Systematic Survey of Self-Protecting Software Systems,” ACM Transactions Auton. Adapt. Syst., vol. 8, no. 4, pp. 17:1–17:41, Jan. 2014. [24] M. Riegler, J. Sametinger, and M. Vierhauser, “A Distributed MAPE-K Framework for Self-Protective IoT Devices,” in 2023 IEEE/ACM 18th Symposium on Software Engineering for Adaptive and Self-Managing Systems (SEAMS), May 2023, pp. 202–208. [25] E. J. Beggs, J. V. Tucker, and V. Wang, “On human-centred security: a new systems model based on modes and mode transitions,” Journal of Cybersecurity, vol. 11, no. 1, p. tyaf023, Jan. 2025. [Online]. Available: https://academic.oup.com/cybersecurity/ article/doi/10.1093/cybsec/tyaf023/8246083
System Support for CPS Software Rejuvenation,” IEEE Transactions on Emerging Topics in Computing, vol. 11, no. 3, pp. 594–604, Jul. 2023. [Online]. Available: https://ieeexplore.ieee.org/document/10106769/ [27] D. Sisodia, S. Mergendahl, J. Li, and H. Cam, “Securing the Smart Home via a Two-Mode Security Framework,” in Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering. Cham: Springer International Publishing, 2018, pp. 22–42, iSSN: 1867-8211, 1867-822X. [Online]. Available: http://link.springer.com/10.1007/978-3-030-01701-9_2 [28] A. Rao, N. A. Carreón, R. Lysecky, and J. Rozenblit, “FIRE: A Finely Integrated Risk Evaluation Methodology for Life-Critical Embedded Systems,” Information, vol. 13, no. 10, p. 487, Oct. 2022. [Online]. Available: https://www.mdpi.com/2078-2489/13/10/ 487 [29] K. Goseva-Popstojanova, Feiyi Wang, Rong Wang, Fengmin Gong, K. Vaidyanathan, K. Trivedi, and B. Muthusamy, “Characterizing intrusion tolerant systems using a state transition model,” in Proceedings of the DARPA Information Survivability Conference and Exposition II. Anaheim, CA, USA: IEEE, 2001, pp. 211–221. [30] A. Ahmad, A. W. Malik, A. Alreshidi, W. Khan, and M. Sajjad, “Adaptive Security for Self-Protection of Mobile Computing Devices,” Mobile Networks and Applications, vol. 28, no. 2, pp. 653–672, Apr. 2023. [31] A. Avizienis, J.-C. Laprie, B. Randell, and C. Landwehr, “Basic concepts and taxonomy of dependable and secure computing,” IEEE Transactions on Dependable and Secure Computing, vol. 1, no. 1, pp. 11–33, Jan. 2004. [32] M. Riegler, J. Sametinger, and J. W. Rozenblit, “Context-Aware Security Modes For Medical Devices,” in 2022 Annual Modeling and Simulation Conference (ANNSIM). San Diego, CA, USA: IEEE, Jul. 2022, pp. 372–382. [Online]. Available: https://ieeexplore.ieee.org/document/9859283/ [33] B. Wong, “Points of view: Color blindness,” Nature Methods, vol. 8, no. 6, pp. 441–441, Jun. 2011. [34] B. Penzenstadler, A. Raturi, D. Richardson, and B. Tomlinson, “Safety, Security, Now Sustainability: The Nonfunctional Requirement for the 21st Century,” IEEE Software, vol. 31, no. 3, pp. 40–47, May 2014. [Online]. Available: https://ieeexplore.ieee.org/document/6728940/ [35] International Organization for Standardization, “Systems and software engineering — systems and software quality requirements and evaluation (square) — product quality model,” International Organization for Standardization, Standard ISO/IEC 25010:2023, 2023. [36] M. Javaid, A. Haleem, R. P. Singh, S. Rab, and R. Suman, “Significant applications of Cobots in the field of manufacturing,” Cognitive Robotics, vol. 2, pp. 222–233, 2022. [Online]. Available: https://linkinghub.elsevier.com/retrieve/pii/S2667241322000209 [37] J. Li, M. Zhang, N. Li, D. Weyns, Z. Jin, and K. Tei, “Generative AI for Self-Adaptive Systems: State of the Art and Research Roadmap,” ACM Transactions on Autonomous and Adaptive Systems, vol. 19, no. 3, pp. 1–60, Sep. 2024. [Online]. Available: https://dl.acm.org/doi/10.1145/3686803 [38] R. Chaganti, R. V. Boppana, V. Ravi, K. Munir, M. Almutairi, F. Rustam, E. Lee, and I. Ashraf, “A Comprehensive Review of Denial of Service Attacks in Blockchain Ecosystem and Open Challenges,” IEEE Access, vol. 10, pp. 96 538–96 555, 2022. [Online]. Available: https://ieeexplore.ieee.org/document/9881505/ [39] A. Matathammal, K. Gupta, L. Lavanya, A. V. Halgatti, P. Gupta, and K. Vaidhyanathan, “Edgemlbalancer: A self-adaptive approach for dynamic model switching on resourceconstrained edge devices,” in Proceedings of the IEEE 22nd International Conference on Software Architecture Companion. Odense, Denmark: IEEE, 2025, pp. 543–552. [40] P. Bambazek, I. Groher, and N. Seyff, “Requirements engineering for sustainable software systems: a systematic mapping study,” Requirements Engineering, vol. 28, no. 3, pp. 481–505, 2023. [41] I. Fatima and P. Lago, “Software architecture assessment for sustainability: A case study,” in Software Architecture - 18th European Conference, ECSA 2024, Luxembourg City, Luxembourg, September 3-6, 2024, Proceedings, ser. Lecture Notes in Computer Science, vol. 14889. Springer, 2024, pp. 233–249. [42] S. Oyedeji, M. A. Khan, P. Puhtila, O. Weerakoon, T. Mäkilä, M. O. Adisa, B. Naqvi, and S. Auvinen, “Green coding: State of practice,” in 11th International Conference on ICT for Sustainability, ICT4S 2025, Dublin, Ireland, June 9-13, 2025. IEEE, 2025, pp. 91–99. [43] R. Chitchyan, C. Becker, S. Betz, L. Duboc, B. Penzenstadler, N. Seyff, and C. C. Venters, “Sustainability design in requirements engineering: state of practice,” in Proceedings of the 38th International Conference on Software Engineering Companion, ser. ICSE ’16. New York, NY, USA: ACM, 2016, p. 533–542. [Online]. Available: https://doi.org/10.1145/2889160.2889217 [44] L. Duboc, S. Betz, B. Penzenstadler, S. A. Kocak, R. Chitchyan, O. Leifler, J. Porras, N. Seyff, and C. C. Venters, “Do we really know what we are building? raising awareness of potential sustainability effects of software systems in requirements engineering,” in 2019 IEEE 27th International Requirements Engineering Conference (RE). Jeju Island, Korea (South): IEEE, 2019, pp. 6–16. [45] R. Ali, F. Dalpiaz, and P. Giorgini, “A goal-based framework for contextual requirements modeling and analysis,” Requirements Engineering, vol. 15, no. 4, pp. 439–458, Nov. 2010. [46] H. Bhatt, S. Arun, A. Kakran, and K. Vaidhyanathan, “Towards Architecting Sustainable MLOps: A Self-Adaptation Approach,” in 2024 IEEE 21st International Conference on Software Architecture Companion (ICSA-C), Jun. 2024, pp. 179–182.
7
PREPRINT – accepted for publication at the 7th IEEE International Conference on Autonomic Computing and Self-Organizing Systems (ACSOS) 2026 [47] H. Bhatt, S. Biswas, S. Rakhunathan, and K. Vaidhyanathan, “HarmonE: A Self-adaptive Approach to Architecting Sustainable MLOps,” in Software Architecture, V. Andrikopoulos, C. Pautasso, N. Ali, J. Soldani, and X. Xu, Eds. Cham: Springer Nature Switzerland, 2026, vol. 15929, pp. 38–55. [48] Z. Chen, J. Li, N. Li, W. Jiao, and E. Kang, “Context-Aware Proactive Self-Adaptation: A Two-layer Model Predictive Control Approach,” ACM Transactions on Autonomous and Adaptive Systems, p. 3708998, Dec. 2024. [49] T. Halabi, M. Bellaiche, and B. C. M. Fung, “Towards Adaptive Cybersecurity for Green IoT,” in Proceedings of the 2022 IEEE International Conference on Internet of Things and Intelligence Systems. IEEE, Nov. 2022, pp. 64–69. [50] W. Xiong and R. Lagerström, “Threat modeling – A systematic literature review,” Computers & Security, vol. 84, pp. 53–69, Jul. 2019. [Online]. Available: https://linkinghub.elsevier.com/retrieve/pii/S0167404818307478 [51] O. Gadyatskaya and N. D. Schiele, “A limited technical background is sufficient for attack-defense tree acceptability,” in Proceedings of the 34th USENIX conference on security symposium, ser. Sec ’25. Seattle, WA, USA: USENIX Association, 2025. [52] C. A. Ericson, Hazard Analysis Techniques for System Safety, 1st ed. Wiley, Jul. 2005. [53] W. E. Vesely, F. F. Goldberg, N. H. Roberts, and D. F. Haasl, “Fault Tree Handbook,” U. S. Nuclear Regulatory Commission, Washington, D. C., Tech. Rep. NUREG-0492, Jan. 1981. [Online]. Available: https://www.nrc.gov/docs/ML1007/ML100780465.pdf [54] E. Ruijters and M. Stoelinga, “Fault tree analysis: A survey of the state-of-the-art in modeling, analysis and tools,” Computer Science Review, vol. 15-16, pp. 29–62, Feb. 2015. [55] L. Duboc, B. Penzenstadler, J. Porras, S. Akinli Kocak, S. Betz, R. Chitchyan, O. Leifler, N. Seyff, and C. C. Venters, “Requirements engineering for sustainability:
an awareness framework for designing software systems for a better tomorrow,” Requirements Engineering, vol. 25, no. 4, pp. 469–492, Dec. 2020. [Online]. Available: https://link.springer.com/10.1007/s00766-020-00336-y [56] S. Betz, N. Wulf, D. Lammert, B. Penzenstadler, C. C. Venters, and L. Duboc, “The Sustainability Awareness Framework,” 2022. [57] T. Alladi, V. Chamola, and S. Zeadally, “Industrial Control Systems: Cyberattack trends and countermeasures,” Computer Communications, vol. 155, pp. 1–8, Apr. 2020. [Online]. Available: https://linkinghub.elsevier.com/retrieve/pii/S0140366419319991 [58] T. Vogel, “Software Engineering for Self-Adaptive Systems exemplars repository,” 2026. [Online]. Available: http://self-adaptive.org/exemplars/ [59] Y.-J. Shin, L. Liu, S. Hyun, and D.-H. Bae, “Platooning LEGOs: An Open Physical Exemplar for Engineering Self-Adaptive Cyber-Physical Systems-of-Systems,” in Proceedings of the 2021 International Symposium on Software Engineering for Adaptive and Self-Managing Systems (SEAMS), May 2021, pp. 231–237. [60] M. U. Iftikhar, G. S. Ramachandran, P. Bollansee, D. Weyns, and D. Hughes, “DeltaIoT: A Self-Adaptive Internet of Things Exemplar,” in Proceedings of the IEEE/ACM 12th International Symposium on Software Engineering for Adaptive and Self-Managing Systems. IEEE, May 2017, pp. 76–82. [61] G. A. Moreno, B. Schmerl, and D. Garlan, “SWIM: an exemplar for evaluation and comparison of self-adaptation approaches for web applications,” in Proceedings of the 13th International Conference on Software Engineering for Adaptive and Self-Managing Systems. ACM, May 2018, pp. 137–143.
8